Sceawere

Vulnerability Detail

CVE-2026-95391UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ZigBee ZCL Dissector DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-416: Use After Free
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:15.310Z",
  "pubdate": "2026-09-29T10:17:15.310Z",
  "executiveSummary": "A denial-of-service (DoS) vulnerability has been identified within the ZigBee Cluster Library (ZCL) protocol dissector affecting versions 4.6.0 through 4.6.8.\nThe vulnerability stems from improper handling of specific protocol data units, leading to a crash of the dissector process.\nSuccessful exploitation allows a remote, unauthenticated attacker to cause a crash of the dissection engine, effectively disrupting the monitoring and analysis of ZigBee network traffic.\nThis vulnerability primarily affects software stacks or analysis tools that utilize the affected ZCL dissector component for packet parsing and inspection.\nThe risk implication is significant for environments relying on real-time protocol analysis for security monitoring or network management, as the crash interrupts the visibility into the ZigBee environment.\nExploitation does not require prior authentication or privileged access to the target host; however, the attacker must have the ability to inject or transmit malformed ZigBee packets into the network path where the dissector operates.\nThis vulnerability highlights a critical failure in input validation routines when processing specific ZCL packet structures.",
  "technicalDetails": "The vulnerability exists within the ZigBee Cluster Library (ZCL) dissector engine, specifically affecting parsing logic implemented in versions 4.6.0 through 4.6.8.\nThe root cause is an improper handling of malformed packet structures or out-of-range parameters within the ZCL payload. When the dissector attempts to parse a crafted ZCL command, it triggers an unhandled exception or memory access violation, leading to an immediate crash of the dissector service.\nThe attack flow initiates when an adversary constructs a malicious packet encapsulating a malformed ZCL frame. This packet is transmitted over the wireless medium or through a network gateway that feeds into the vulnerable dissection engine.\nUpon receiving the malicious packet, the dissector attempts to iterate through the frame fields. If the input contains unexpected length values or inconsistent field identifiers, the parsing function fails to perform adequate bounds checking or validation. This leads to an illegal memory access or an infinite loop, resulting in a process termination (denial of service).\nBecause the dissector component is typically responsible for the integrity of packet analysis, a crash disrupts the entire traffic monitoring chain. In many deployment scenarios, the dissector may run as part of a packet capture utility, an intrusion detection system (IDS), or a protocol gateway.\nExploitation is possible over the air (OTA) provided the attacker is within the radio range of the network or via an intermediary system that forwards the malformed traffic to the vulnerable software component.\nThe impact is strictly related to availability; the attacker cannot achieve code execution through this specific vulnerability, but the persistent crashing of the dissection process effectively blinds the security and management tools relying on it.\nNo authentication is required to trigger this vulnerability, as the dissection engine processes incoming traffic asynchronously and blindly parses headers before verifying the payload's source or legitimacy.\nThe technical failure is rooted in the absence of robust input sanitation mechanisms within the C/C++ based parsing logic, which fails to account for edge cases in the ZigBee Cluster Library protocol specifications.\nThe affected versions (4.6.0 - 4.6.8) indicate a systemic deficiency in the parser's state machine that persists across these iterative updates until a corrective patch is applied."
}
CVE-2026-95391: ZigBee ZCL Dissector DoS (MEDIUM Severity, CVSS: 5.5) | Sceawere